By Michael Rinehart, VP of AI, Securiti
Enacted on May 25, 2018, the EU General Data Protection Regulation (GDPR) has significantly impacted global privacy regulations. Emphasizing the importance of obtaining consent before processing information, GDPR remains relevant today. Simultaneously, the field of artificial intelligence (AI) is experiencing rapid advancements, particularly with the transformative force of Generative AI automating tasks and reshaping data handling.
Legal Challenges Surrounding Generative AI
The surge in AI technologies, especially Generative AI, is creating new pressure on responsible data management. The recent investigation by the UK’s Information Commissioner’s Office (ICO) into the legality of web scraping for training generative AI models underscores the intricate challenges organizations face in adapting to these technological shifts.
Generative AI technologies promise industry transformation, but responsible implementation necessitates robust data governance practices. Sensitive data, errored information, and bias in datasets can have significant ramifications for a company making available products powered by Generative AI. But even models designated for internal use can pose serious risks to organizations because they are directly accessible through an interface, and, ultimately as a file on disk, can be leaked. It behooves organizations to adopt comprehensive AI Governance frameworks to validate the correctness of data and to safeguard AI models as a new interface for accessing it.
Key Elements of Generative AI Governance Framework
Responsible AI implementation requires a robust AI Governance framework. Primary among the components in such a framework are those already features in Data Governance frameworks, including strict access controls, data anonymization (if appropriate), data subject rights, and so on. However, a holistic framework should also include additional components that may be overlooked:
- Regular Reviews and Assessments: Over time, the capabilities and underlying technologies of a deployed AI system will change. Regular assessments of AI systems are critical to ensuring that relevant changes are surfaced and responsibly managed to meet expectations and regulatory requirements.
- Continuous Training: Governance frameworks apply to layers of complex technologies and best practices that often require multiple functions to evaluate and implement properly. This is especially true of AI technologies. Providing ongoing training to employees will allow them to assess and implement the framework’s requirements more effectively.
- Regular & Relevant Updates: The safety of Generative AI systems is a rapidly growing field, with new technologies being made available on a seemingly monthly basis. Staying informed about new capabilities and adopting relevant ones is crucial for defending AI systems against new attacks and allowing organizations to maintain a competitive edge. Likewise, an AI Governance framework should keep pace as new threats and defenses are recognized to ensure that proper solutions are deployed.
- Centralized Oversight: An AI Governance may span many functions, but ultimately the success of its implementation is determined by its ability to be consistently and correctly interpreted as well as enforced. Establish a centralized body for this critical function.
By implementing these steps, organizations can ensure that their existing AI systems are responsibly deployed and managed, and they can be confident that they will be able to maintain a strong posture in the face of a field undergoing significant shifts on a frequent basis.
##
ABOUT THE AUTHOR
Michael Rinehart, VP of AI, Securiti
Michael Rinehart is the VP of Artificial Intelligence at Securiti. Previously, Michael was a chief scientist at Elastica/Blue Coat Systems, leading the design and development of many of its data science technologies. He has deployed machine learning and data science systems to numerous domains, including Internet security, healthcare, power electronics, automotives, and marketing. Prior to joining Elastica, he led the research and development of a machine learning-based wireless communications jamming technology at BAE Systems. Michael has a B.S. from University of Maryland and an M.S. and Ph.D. in electrical engineering from the Massachusetts Institute of Technology.





